CVE-2022-24145: High severity Tenda AX3 firmware vulnerability
Published Feb 4, 2022
·Updated
Tenda AX3 v16.03.12.10CN was discovered to contain a stack overflow in the function formWifiBasicSet. This vulnerability allows attackers to cause a Denial of Service (DoS) via the security and security5g parameters.
Affected Software
2 affected components
Tenda AX3 firmware=16.03.12.10_cn
Tenda AX3
Event History
Feb 4, 2022
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
Description
Frequently Asked Questions
1
What is CVE-2022-24145?
CVE-2022-24145 is a vulnerability discovered in Tenda AX3 v16.03.12.10_CN that allows attackers to cause a Denial of Service (DoS) via the security and security_5g parameters.
2
How severe is CVE-2022-24145?
CVE-2022-24145 has a severity rating of 7.5, which is considered high.
3
What is the affected software for CVE-2022-24145?
The affected software for CVE-2022-24145 is Tenda AX3 v16.03.12.10_CN firmware.
4
How can attackers exploit CVE-2022-24145?
Attackers can exploit CVE-2022-24145 by manipulating the security and security_5g parameters.
5
Is Tenda AX3 vulnerable to CVE-2022-24145?
Yes, Tenda AX3 v16.03.12.10_CN firmware is vulnerable to CVE-2022-24145.